The news
Data theft extortion, in which criminals steal records and threaten to publish them rather than encrypt systems, is shifting to business applications. On September 25, Google researchers said ShinyHunters had renewed attacks on Oracle (ORCL) PeopleSoft systems holding HR, payroll and student records.
According to Mandiant and Google Threat Intelligence Group, the group Google tracks as UNC6240 first exploited CVE-2026-35273, a flaw in PeopleSoft's Environment Management Hub, as a zero-day between May 27 and June 9, 2026, mainly against universities. Oracle issued an out-of-band security alert on June 10. In September the group returned, bypassing web application firewall rules by URL-encoding a single character in the request path, and hit dozens of systems across higher education, technology, healthcare, transportation, government and other sectors.
Google's hunting guidance points at what the attackers want: it tells defenders to review database logs for bulk queries of HR, payroll and student records, to watch for large archive files and rsync or SSH transfers, and to prepare for extortion messages and leak-site postings. It also urges rotating every credential the PeopleSoft service account can read, including database connection strings and cloud credentials.
SaaS platforms face the same playbook. In August, Google described UNC6671, a group operating under several extortion brands, that phoned employees posing as IT help desks, captured logins through fake sign-in pages, then used scripts to pull files from Microsoft 365, Okta and other cloud services. By July it had shifted toward financial services, private equity and law firms. Google said 18 of its bitcoin wallets received 141.65 bitcoin, about $10.69 million, between January 7 and May 12, 2026, with initial demands typically ranging from $1 million to more than $3 million and often negotiated down by 50% to 75%.
Anthropic's September threat report adds scale: it says operators suspected of being ShinyHunters affiliates breached one SaaS provider and used that foothold to extract data belonging to roughly 200 of its downstream customer organizations. The same pressure tactic appears outside ERP and SaaS. CenterPoint Energy said in a September 14 SEC filing that customer data was taken through one of its external-facing systems; BleepingComputer reported that a different actor, using the alias 4d722e4d656f77, said it scraped the records through a public API that lacked rate limiting, then leaked them, claiming the company had ignored its messages.
The numbers
- PeopleSoft zero-day exploitation window
- May 27 – June 9, 2026
- UNC6671 wallet receipts (18 wallets, Jan 7 – May 12)
- 141.65 BTC (~$10.69M)
- UNC6671 typical initial demand
- $1M to more than $3M
- Downstream organizations whose data was taken via one SaaS breach (Anthropic)
- ~200
Why CEOs should care
For CFOs, these attacks target systems finance often owns: ERP, payroll, HR and the SaaS tools that store deal documents. Ask who is accountable for security in each, whether patches like Oracle's June alert were applied within days, and whether anyone would see a bulk export of payroll data at 3 a.m. Google's advice to alert on bulk queries and scripted downloads is cheap compared with an extortion payment.
For CISOs, close the gaps these groups exploit. Shrink the exposed ERP surface, as Google does in advising PeopleSoft customers to disable the Environment Management Hub service, or remove it entirely on single-server setups. Treat web application firewall rules as a delay, not a fix, since a single encoded character defeated them. For SaaS, Google's UNC6671 guidance calls for phishing-resistant authentication, sign-in only from managed devices, shorter sessions and alerts when files are accessed by scripting tools rather than browsers.
For boards, extortion without encryption changes the crisis. Operations keep running, so the pressure comes from regulators, customers and leak sites. Ask whether the incident plan covers negotiation policy, legal privilege, notification timelines and who speaks publicly, and whether it has been rehearsed with data theft, not ransomware, as the scenario.
The bigger picture
The shift has a simple logic. Encrypting a network is noisy; quietly copying data from an internet-facing application or a cloud tenant can be faster and may go unseen until the ransom note arrives. The groups are also competitive: SecurityWeek reported on September 25 that ShinyHunters claimed to have compromised the leak site of rival extortion gang Cl0p and demanded an eight-figure payment. For companies, the practical point is that the most sensitive data often sits in applications owned by HR, finance or a SaaS vendor, outside the security team's day-to-day view.
What’s next
Expect more victims of the PeopleSoft campaign to surface through breach notifications and leak-site listings in the coming weeks. Companies running PeopleSoft should confirm the June patch is in place, check for the web shells Google lists, and be ready for extortion contact even if they believe they were not breached. Those that outsource PeopleSoft hosting should ask their provider for written confirmation of both steps.
What “Fact-checked” means
Fact-checking means testing a story’s facts against the evidence before it is published. This story went through at least two separate checks before this version was published.
- What we checked
- Its names, figures, dates, job titles, quotes and who said what were checked against the story’s sources, including its main source where it could be opened. The headline was checked for accuracy and overstatement.
- How
- A first check reviewed the whole story. If it passed, a second, skeptical check went back to the sources to look for mistakes in the most important facts. If a check flagged the story, it was edited to fix the problems found, and a separate re-check then reviewed the whole story again.
- Who
- The checks are made by our newsroom, as steps kept separate from the writing, under rules set by our editor, Hussein Mukhtar. A story the checks still flag is held for the editor, who decides whether it is fixed, published or dropped.
- If something is wrong
- “Fact-checked” does not mean error-free. If a material error is found after publication, we correct the story and add a note saying what changed. Report an error









